This release includes 1 security fix for security teams reviewing exposed deployments.
Published 19d
AI Agents & Assistants
✓ No known CVEs patched
This release patches 1 known CVE
Affected surfaces
rce_ssrf
Summary
AI summaryFix path traversal vulnerability in validate_relative_path and add write_file tool
Full changelog
Added
write_filetool — agents can now create new files (refuses to overwrite existing ones)- Integration tests for
edit_filewith multi-byte (emoji) content
Changed
- Personality adjustments
- Better
write_fileoutput formatting
Fixed
- Fix path traversal vulnerability in
validate_relative_pathfor non-existent paths - Fix: guarantee all markers are removed after agent completes, not just context markers
- Make keyboard Space-bar polling Unix-only (
termiosunavailable on Windows); no-op on non-Unix platforms
Security Fixes
- Fix path traversal vulnerability in `validate_relative_path` for non‑existent paths
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About rik
All releases →Beta — feedback welcome: [email protected]